
AI-Powered CVE Analysis for WordPress Plugins
We use AI to automate the differential analysis between vulnerable and patched plugin versions to understand and interpret the security issues. What we share here is research-grade proof of concept demonstrations that are then fed back into our endpoint firewall service.
WordPress Proof of Concepts
AI-assisted vulnerability analysis with PoC demonstration
June 10, 2026
CVE-2026-10795: UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 Unauthenticated Authentication Bypass via UpdraftCentral udrpc PoC, Patch Analysis & Rule
High CVE-2026-10795 in Updraftplus (CVSS 8.1): UpdraftPlus: WP Backup & Migration Plugin. Atomic Edge summarizes impact, exploitability, and patch details. Update to 1.26.5.
June 10, 2026
CVE-2026-2827: Open User Map PRO <= 1.4.31 Unauthenticated Stored Cross-Site Scripting via 'oum_location_notification' PoC, Patch Analysis & Rule
Medium CVE-2026-2827 in Open User Map Pro (CVSS 4.7): Open User Map PRO. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 10, 2026
CVE-2026-8940: WP Meta Sort Posts <= 0.9 Cross-Site Request Forgery to Plugin Settings Update PoC, Patch Analysis & Rule
Medium CVE-2026-8940 in Wp Meta Sort Posts (CVSS 4.3): WP Meta Sort Posts. Atomic Edge summarizes impact, exploitability, and patch details.
June 10, 2026
CVE-2026-9185: 6Storage Rentals <= 2.22.0 Unauthenticated Insecure Direct Object Reference to Arbitrary User Disclosure and Modification via 'userId' Parameter PoC, Patch Analysis & Rule
High CVE-2026-9185 in 6storage Rentals (CVSS 7.5): 6Storage Rentals. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 10, 2026
CVE-2026-8904: FastPicker, an order picker and order management system (oms) for WooCommerce on steroids <= 1.0.2 Cross-Site Request Forgery via Settings Save PoC, Patch Analysis & Rule
Medium CVE-2026-8904 in Fastpicker (CVSS 4.3): FastPicker, an order picker and order management system (oms) for WooCommerce on steroids. Atomic Edge summarizes impact, exploitability, and patch details.
June 10, 2026
CVE-2026-8907: WP-Ultimate-Map <= 1.1 Cross-Site Request Forgery to Stored Cross-Site Scripting via 'zoom-level' Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-8907 in Wp Ultimate Map (CVSS 6.1): WP-Ultimate-Map. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 10, 2026
CVE-2026-8910: WP Emoticon Rating <= 1.0.1 Cross-Site Request Forgery to Reflected Cross-Site Scripting via 'emo_settings' Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-8910 in Wp Emoticon Rating (CVSS 6.1): WP Emoticon Rating. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 10, 2026
CVE-2026-8909: WpMobi <= 0.0.3 Cross-Site Request Forgery via save_general_settings Action PoC, Patch Analysis & Rule
Medium CVE-2026-8909 in Wp Mobi (CVSS 4.3): WpMobi. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 10, 2026
CVE-2026-8902: AJAX Report Comments <= 2.0.4 Cross-Site Request Forgery to Settings Update PoC, Patch Analysis & Rule
Medium CVE-2026-8902 in Report Comments (CVSS 4.3): AJAX Report Comments. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 10, 2026
CVE-2026-8499: Helpfulcrowd Product Reviews <= 1.2.9 Inccorect Authorization via Type Juggling in 'token' Parameter to Arbitrary Settings Update PoC, Patch Analysis & Rule
Medium CVE-2026-8499 in Helpfulcrowd Product Reviews (CVSS 5.3): Helpfulcrowd Product Reviews. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 10, 2026
CVE-2026-8977: WP GDPR Cookie Consent <= 1.0.0 Authenticated (Subscriber+) Stored Cross-Site Scripting via 'ninja_gdpr_ajax_actions' AJAX Action PoC, Patch Analysis & Rule
Medium CVE-2026-8977 in Wp Gdpr Cookie Consent (CVSS 6.4): WP GDPR Cookie Consent. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 10, 2026
CVE-2026-8841: Extra Settings for RocketChat <= 0.1 Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes PoC, Patch Analysis & Rule
Medium CVE-2026-8841 in Extra Settings For Rocketchat (CVSS 6.4): Extra Settings for RocketChat. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 10, 2026
CVE-2026-7662: ePaperFlip Publisher <= 1 Authenticated (Contributor+) Stored Cross-Site Scripting via 'publicationid' Shortcode Attribute PoC, Patch Analysis & Rule
Medium CVE-2026-7662 in Epaperflip Publisher (CVSS 6.4): ePaperFlip Publisher. Atomic Edge summarizes impact, exploitability, and patch details.
June 10, 2026
CVE-2026-10862: Accordions <= 2.3.23 Authenticated (Custom+) Stored Cross-Site Scripting via Accordion Body Field PoC, Patch Analysis & Rule
Medium CVE-2026-10862 in Accordions (CVSS 6.4): Accordions. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 10, 2026
CVE-2026-5714: Enable Media Replace <= 4.1.8 Authenticated (Author+) Stored Cross-Site Scripting via 'location_dir' Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-5714 in Enable Media Replace (CVSS 6.4): Enable Media Replace. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 4.1.9.
June 10, 2026
CVE-2026-9851: Booking Package <= 1.7.16 Authenticated (Editor+) Privilege Escalation via Account Takeover to updateUser AJAX Action PoC, Patch Analysis & Rule
High CVE-2026-9851 in Booking Package (CVSS 7.2): Booking Package. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.7.17.
June 10, 2026
CVE-2026-3011: Recipe Card Blocks Lite <= 3.4.13 Authenticated (Author+) Stored Cross-Site Scripting via 'summary' and 'notes' PoC, Patch Analysis & Rule
Medium CVE-2026-3011 in Recipe Card Blocks By Wpzoom (CVSS 6.4): Recipe Card Blocks Lite. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 3.4.14.
June 10, 2026
CVE-2026-7556: FV Flowplayer Video Player <= 7.5.49.7212 Unauthenticated Stored Cross-Site Scripting via Comment Text PoC, Patch Analysis & Rule
High CVE-2026-7556 in Fv Wordpress Flowplayer (CVSS 7.2): FV Flowplayer Video Player. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
June 10, 2026
CVE-2026-9829: Photo Gallery by 10Web <= 1.8.41 Authenticated (Contributor+) SQL Injection via 'compact_album_order_by' Shortcode Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-9829 in Photo Gallery (CVSS 6.5): Photo Gallery by 10Web. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage. Update to 1.8.42.
June 10, 2026
CVE-2026-9594: WP Maps <= 4.9.4 Authenticated (Admin+) Stored Cross-Site Scripting via 'location_messages' Parameter PoC, Patch Analysis & Rule
Medium CVE-2026-9594 in Wp Google Map Plugin (CVSS 4.4): WP Maps. Atomic Edge summarizes impact, exploitability, and patch details, with WAF rule coverage.
How Atomic Edge Works
Simple Setup. Powerful Security.
Atomic Edge acts as a security layer between your website & the internet — inspecting, filtering, and blocking malicious traffic before it ever reaches
your application.
